Privacy Policy
This Privacy Policy describes how FeedGrid ("we", "us", or "our") collects, uses, and protects information when you use the FeedGrid Shopify application ("the Service"). We are committed to protecting your privacy and handling your data responsibly.
1. Who We Are
FeedGrid is a Shopify application that enables merchants to display their Instagram and TikTok feed content on their storefront. For privacy enquiries, contact us at [email protected].
2. Information We Collect
We collect only the minimum data necessary to provide the Service:
| Data | Purpose | Storage |
|---|---|---|
| Shopify shop domain | Identify your store and deliver the correct feed | Cloudflare D1 database |
| Shopify access token | Read product data for shoppable post features | Encrypted in Cloudflare D1 |
| Instagram access token | Fetch your Instagram feed on your behalf | Encrypted in Cloudflare D1 and KV |
| TikTok access token | Fetch your TikTok video list on your behalf | Encrypted in Cloudflare D1 and KV |
| Social media post metadata | Display your feed on your storefront (image URLs, captions, timestamps) | Cached in Cloudflare KV (24h TTL) |
| Feed display settings | Remember your layout preferences | Cloudflare D1 database |
| Subscription plan status | Determine which features are available to your account | Cloudflare D1 database |
We do not collect: personal data of your customers, browsing behaviour, cookies, or any data beyond what is listed above.
3. How We Use Your Information
We use the data we collect solely to:
- Authenticate your store and social media connections
- Fetch and cache your social media feed content
- Display your feed on your Shopify storefront
- Manage your subscription and billing through Shopify
- Automatically refresh access tokens to maintain uninterrupted service
- Respond to support requests you send to us
We do not sell, rent, or share your data with third parties for marketing purposes.
4. Third-Party Services
The Service integrates with the following third-party platforms. Your use of these integrations is also subject to their respective privacy policies:
- Shopify — storefront platform and billing. Shopify Privacy Policy
- Meta / Instagram — Instagram Graph API for feed retrieval. Meta Privacy Policy
- TikTok — TikTok Display API for video feed retrieval. TikTok Privacy Policy
- Cloudflare — infrastructure provider (Workers, D1, KV, Pages). Cloudflare Privacy Policy
5. Data Security
All access tokens (Shopify, Instagram, TikTok) are encrypted at rest using AES-GCM encryption before being stored. Data is stored on Cloudflare's infrastructure, which operates globally distributed data centres with enterprise-grade security. We use HTTPS for all data transmission.
6. Data Retention
We retain your data for as long as your store has FeedGrid installed. When you uninstall the app:
- Your account is marked inactive immediately
- All stored data (tokens, settings, cached feed) is deleted within 48 hours
- Cached feed data (KV store) expires automatically within 24 hours
7. Your Rights
Depending on your location, you may have rights regarding your personal data including the right to access, correct, or delete data we hold about you. To exercise these rights, contact us at [email protected]. We will respond within 30 days.
If you are located in the European Economic Area, you have rights under the General Data Protection Regulation (GDPR). If you are located in Australia, you have rights under the Australian Privacy Act 1988.
8. Shopify GDPR Webhooks
As a Shopify app, we comply with Shopify's mandatory GDPR webhook requirements:
- Customer data request: We do not store personal data about your customers. Requests will receive confirmation of this.
- Customer data deletion: We do not store personal data about your customers. No customer data deletion is required.
- Shop data deletion: Upon receiving a shop redact webhook, all merchant data is permanently deleted within 48 hours.
9. Cookies
The FeedGrid storefront widget does not set any cookies on your customers' browsers. The FeedGrid admin application (accessed via Shopify admin) uses only session cookies required by Shopify's embedded app framework.
10. Children's Privacy
The Service is not directed at children under 13 years of age. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the app. The "Last updated" date at the top of this page will reflect when changes were made.
12. Contact Us
For any privacy-related questions, data requests, or concerns, please contact:
FeedGrid
Email: [email protected]